VendorsVMwarevsphereall versions
Vulnerabilities

VMware vSphere

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

63CVEs
CVE-2023-0185
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign conversion issuescasting an unsigned primitive to signed may lead to denial of service or information disclosure.
Published 2023-04-01 · Modified
7.1EPSS 0.002
CVE-2023-0181
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.
Published 2023-04-01 · Modified
7.1EPSS 0.002
CVE-2023-25517
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering.
Published 2023-07-03 · Modified
7.1EPSS 0.002
CVE-2020-27216
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability.
Published 2020-10-23 · Modified
7.0EPSS 0.044
CVE-2022-34674
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information leak.
Published 2022-12-30 · Modified
6.8EPSS 0.003
CVE-2022-34678
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause a null-pointer dereference, which may lead to denial of service.
Published 2022-12-30 · Modified
6.5EPSS 0.002
CVE-2024-0093
CVE
Published 2024-06-13 · Modified
6.5EPSS 0.002
CVE-2023-31018
CVE
Published 2023-11-02 · Modified
6.5EPSS 0.002
CVE-2023-0197
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service.
Published 2023-04-01 · Modified
6.5EPSS 0.002
CVE-2021-1061
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Published 2021-01-08 · Modified
6.3EPSS 0.002
CVE-2023-31026
CVE
Published 2023-11-02 · Modified
6.0EPSS 0.002
CVE-2021-1066
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to unexpected consumption of resources, which in turn may lead to denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Published 2021-01-08 · Modified
5.5EPSS 0.003
CVE-2022-34680
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service.
Published 2022-12-30 · Modified
5.5EPSS 0.003
CVE-2022-42259
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service.
Published 2022-12-30 · Modified
5.5EPSS 0.003
CVE-2022-34679
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unhandled return value can lead to a null-pointer dereference, which may lead to denial of service.
Published 2022-12-30 · Modified
5.5EPSS 0.002
CVE-2021-1087
NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), which could allow an attacker to retrieve information that could lead to a Address Space Layout Randomization (ASLR) bypass. This affects vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x (prior to 8.7).
Published 2021-04-29 · Modified
5.5EPSS 0.002
CVE-2022-34682
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a null-pointer dereference, which may lead to denial of service.
Published 2022-12-30 · Modified
5.5EPSS 0.002
CVE-2023-0188
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged user can cause improper restriction of operations within the bounds of a memory buffer cause an out-of-bounds read, which may lead to denial of service.
Published 2023-04-01 · Modified
5.5EPSS 0.002
CVE-2023-31022
CVE
Published 2023-11-02 · Modified
5.5EPSS 0.002
CVE-2024-0092
CVE
Published 2024-06-13 · Modified
5.5EPSS 0.002
CVE-2023-31021
CVE
Published 2023-11-02 · Modified
5.5EPSS 0.002
CVE-2024-0086
CVE
Published 2024-06-13 · Modified
5.5EPSS 0.002
CVE-2012-1512
Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via a crafted log-file entry.
Published 2012-03-16 · Modified
4.3EPSS 0.019
← Prev2 / 2